<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Power Users are Admins who have not made themselves admins yet</title><link>http://blogs.technet.com/jesper_johansson/archive/2006/03/12/421870.aspx</link><description>It seems kind of odd that in 2006 I would still get these questions, but twice in the past week have I had to explain the truth about Power Users to someone. Typically they are organizations who are trying to limit the rights of their users, who right</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Return Quickbooks for Refund</title><link>http://blogs.technet.com/jesper_johansson/archive/2006/03/12/421870.aspx#421927</link><pubDate>Mon, 13 Mar 2006 22:44:16 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:421927</guid><dc:creator>Tales from the Crypto</dc:creator><description>I was going to title this post &amp;amp;quot;Microsoft Representative Says to Return Quickbooks for Refund&amp;amp;quot;.&amp;amp;amp;nbsp;...</description></item><item><title>re: Power Users are Admins who have not made themselves admins yet</title><link>http://blogs.technet.com/jesper_johansson/archive/2006/03/12/421870.aspx#421967</link><pubDate>Tue, 14 Mar 2006 11:35:33 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:421967</guid><dc:creator>BOFH</dc:creator><description>Even regular Users are Admins who have not made themselves admins yet.... </description></item><item><title>re: Power Users are Admins who have not made themselves admins yet</title><link>http://blogs.technet.com/jesper_johansson/archive/2006/03/12/421870.aspx#422096</link><pubDate>Wed, 15 Mar 2006 17:39:02 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:422096</guid><dc:creator>JB</dc:creator><description>I know better than to put users in the Power Users group, for the reasons you described. &amp;nbsp;My question is, what is the purpose of this group in the first place?</description></item><item><title>re: Power Users are Admins who have not made themselves admins yet</title><link>http://blogs.technet.com/jesper_johansson/archive/2006/03/12/421870.aspx#422175</link><pubDate>Thu, 16 Mar 2006 08:39:02 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:422175</guid><dc:creator>jesper</dc:creator><description>BOFH, that is partially true. One might argue, for instance, that any user with physical access to the computer is an admin who haven't made themselves an admin yet.&lt;br&gt;&lt;br&gt;The Power Users group was added long ago to provide a way to run applications that were written assuming elevated privileges. Over time, more and more things were added to the rights of that group and fairly quickly it went past the point where the group provided any isolation. Since then it has been there only for backward compatibility.</description></item><item><title>re: Power Users are Admins who have not made themselves admins yet</title><link>http://blogs.technet.com/jesper_johansson/archive/2006/03/12/421870.aspx#422505</link><pubDate>Mon, 20 Mar 2006 08:43:01 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:422505</guid><dc:creator>Steve Riley</dc:creator><description>It's very simple, really, and I can even put it in simple language.&lt;br&gt;&lt;br&gt; &amp;nbsp; &amp;nbsp;admin = God&lt;br&gt; &amp;nbsp; &amp;nbsp;power user = Christ&lt;br&gt;&lt;br&gt;And, according to the literature,&lt;br&gt;&lt;br&gt; &amp;nbsp; &amp;nbsp;Christ = God&lt;br&gt;&lt;br&gt;It follows, therefore, that:&lt;br&gt;&lt;br&gt; &amp;nbsp; &amp;nbsp;power user = God&lt;br&gt;</description></item><item><title>re: Power Users are Admins who have not made themselves admins yet</title><link>http://blogs.technet.com/jesper_johansson/archive/2006/03/12/421870.aspx#423036</link><pubDate>Fri, 24 Mar 2006 08:28:17 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:423036</guid><dc:creator>lpiatek</dc:creator><description>Christ isn't God! Read John 14:28..&lt;br&gt;</description></item><item><title>re: Power Users are Admins who have not made themselves admins yet</title><link>http://blogs.technet.com/jesper_johansson/archive/2006/03/12/421870.aspx#423125</link><pubDate>Sat, 25 Mar 2006 14:53:05 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:423125</guid><dc:creator>Where can I return my Microsoft Software?</dc:creator><description>Really good points, and I could agree with you more. &amp;nbsp;I'm very ready to implement and also to advise my peer consultants to lower the Domain Users default additionally assigned Local Administrator group down to the Local User level. &amp;nbsp;But if I do that in my SBS 2003 deployment things like Remote Web Workplace no longer work. &amp;nbsp;Yes it is a nasty predicament because that is the number one coolest thing that customers like about SBS ...and there is no comparable competitive product. &amp;nbsp;Plz I'd rather Microsoft fix this not provide refunds and returns.</description></item><item><title>re: Power Users are Admins who have not made themselves admins yet</title><link>http://blogs.technet.com/jesper_johansson/archive/2006/03/12/421870.aspx#423135</link><pubDate>Sat, 25 Mar 2006 20:47:18 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:423135</guid><dc:creator>Susan</dc:creator><description>RWW doesn't need admin rights other that to initially get the Active X controls on the box in the first place.&lt;br&gt;&lt;br&gt;Most software needs admin rights to get the software 'on' the box, after that they don't need normal admin to run.&lt;br&gt;&lt;br&gt;Software typically always needs rights to install, it should not need rights to run.</description></item><item><title>re: Power Users are Admins who have not made themselves admins yet</title><link>http://blogs.technet.com/jesper_johansson/archive/2006/03/12/421870.aspx#423146</link><pubDate>Sun, 26 Mar 2006 07:41:45 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:423146</guid><dc:creator>Scott</dc:creator><description>This is a great thread and article...most of us know this stuff but need to be hit over the head and reminded where we maybe going wrong. Keep up these great articles Jesper I really enjoy reading and getting your perspective.</description></item><item><title>re: Power Users are Admins who have not made themselves admins yet</title><link>http://blogs.technet.com/jesper_johansson/archive/2006/03/12/421870.aspx#423147</link><pubDate>Sun, 26 Mar 2006 08:00:18 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:423147</guid><dc:creator>Susan</dc:creator><description>&lt;a rel="nofollow" target="_new" href="http://www.sbslinks.com/RWW-LUA.htm"&gt;http://www.sbslinks.com/RWW-LUA.htm&lt;/a&gt;&lt;br&gt;&lt;br&gt;Remote web workplace as LUA.&lt;br&gt;&lt;br&gt;It works.&lt;br&gt;&lt;br&gt;The problem is not hacking up the registry, I would argue.. but knowing if what we're hacking is ends up making our systems more insecure.</description></item><item><title>re: Power Users are Admins who have not made themselves admins yet</title><link>http://blogs.technet.com/jesper_johansson/archive/2006/03/12/421870.aspx#423472</link><pubDate>Wed, 29 Mar 2006 10:47:08 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:423472</guid><dc:creator>wkasdo</dc:creator><description>Here is the relevant KB. Helpful if you need to sell this.&lt;br&gt;&lt;br&gt;&lt;a rel="nofollow" target="_new" href="http://support.microsoft.com/default.aspx?scid=kb;en-us;825069"&gt;http://support.microsoft.com/default.aspx?scid=kb;en-us;825069&lt;/a&gt;</description></item><item><title>re: Power Users are Admins who have not made themselves admins yet</title><link>http://blogs.technet.com/jesper_johansson/archive/2006/03/12/421870.aspx#426976</link><pubDate>Tue, 02 May 2006 02:28:44 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:426976</guid><dc:creator>kbiel</dc:creator><description>Sorry for the OT response, but someone else started it :p&lt;br&gt;&lt;br&gt;lpiatek: Read just a few chapter back: &lt;a rel="nofollow" target="_new" href="http://www.biblegateway.com/passage/?book_id=50&amp;amp;chapter=10&amp;amp;verse=30&amp;amp;version=31&amp;amp;context=verse"&gt;http://www.biblegateway.com/passage/?book_id=50&amp;amp;chapter=10&amp;amp;verse=30&amp;amp;version=31&amp;amp;context=verse&lt;/a&gt;&lt;br&gt;&lt;br&gt;Now back to your regularly scheduled topic...&lt;br&gt;&lt;br&gt;While no security system will ever be foolproof, Windows will remain will continue to contain more holes than the titanic as long as MS insists on full backwards compatibility in each release of the OS. &amp;nbsp;I read Raymond Chen's blog regularly and I appreciate the immensity of the problem with breaking backwards compatibility, but there are ways to mend the API (or restructure it entirely) using VMs and compatibility subsystems. &amp;nbsp;Yes, they make the legacy programs run slower or in some crippled fashion, but it has got to be better than the current veneer of security we have to endure because Company X refuses to part with application Y that was written for Windows 3.11.</description></item><item><title>BAD TROUBLESHOOTING 101 (part 3 of many)  Everyone's a local admin!!</title><link>http://blogs.technet.com/jesper_johansson/archive/2006/03/12/421870.aspx#440388</link><pubDate>Thu, 06 Jul 2006 14:59:57 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:440388</guid><dc:creator>Shawn's résumé writing prevention tips</dc:creator><description>&amp;amp;amp;nbsp;&lt;br&gt;OK.&amp;amp;amp;nbsp; gripe time.&amp;amp;amp;nbsp; One of my co-workers was asked by a customer, &amp;amp;quot;Can you prevent a...</description></item><item><title>The Power in Power Users</title><link>http://blogs.technet.com/jesper_johansson/archive/2006/03/12/421870.aspx#499904</link><pubDate>Sun, 05 Nov 2006 20:30:22 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:499904</guid><dc:creator>Mark's Blog</dc:creator><description>&lt;p&gt;Placing Windows user accounts in the Power Users security group is a common approach IT organizations&lt;/p&gt;
</description></item><item><title>RWPT - BAD TROUBLESHOOTING 101 (part 3 of many)  Everyone's a local admin!!</title><link>http://blogs.technet.com/jesper_johansson/archive/2006/03/12/421870.aspx#2620163</link><pubDate>Fri, 07 Dec 2007 12:56:44 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2620163</guid><dc:creator>Shawn's MIIS/ILM tricks, PKI Hints, and Résumé Writing Prevention Tips </dc:creator><description>&lt;p&gt;OK. gripe time. One of my co-workers was asked by a customer, &amp;quot;Can you prevent a local admin from deselecting&lt;/p&gt;
</description></item><item><title>Plan now to eliminate "power users" from your domains</title><link>http://blogs.technet.com/jesper_johansson/archive/2006/03/12/421870.aspx#2870533</link><pubDate>Mon, 11 Feb 2008 21:03:20 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2870533</guid><dc:creator>Steve Riley on Security</dc:creator><description>&lt;p&gt;I've seen some conversations lately about the Power Users group -- how powerful is it, really, and why&lt;/p&gt;
</description></item><item><title>Plan now to eliminate &amp;quot;power users&amp;quot; from your domains | Secure Software Engineering Blog</title><link>http://blogs.technet.com/jesper_johansson/archive/2006/03/12/421870.aspx#2952655</link><pubDate>Sun, 02 Mar 2008 21:59:55 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2952655</guid><dc:creator>Plan now to eliminate "power users" from your domains | Secure Software Engineering Blog</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://www.secure-software-engineering.com/2008/03/02/plan-now-to-eliminate-power-users-from-your-domains/"&gt;http://www.secure-software-engineering.com/2008/03/02/plan-now-to-eliminate-power-users-from-your-domains/&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>Опыты над опытными пользователями</title><link>http://blogs.technet.com/jesper_johansson/archive/2006/03/12/421870.aspx#3151299</link><pubDate>Wed, 12 Nov 2008 01:42:07 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3151299</guid><dc:creator>Mark Russinovich по-русски</dc:creator><description>&lt;p&gt;Организации часто присоединяют учетные записи пользователей Windows к группе безопасности &amp;amp;#171;Опытные&lt;/p&gt;
</description></item><item><title>user | keyongtech</title><link>http://blogs.technet.com/jesper_johansson/archive/2006/03/12/421870.aspx#3189245</link><pubDate>Thu, 22 Jan 2009 05:01:29 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3189245</guid><dc:creator>user | keyongtech</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://www.keyongtech.com/2507723-user"&gt;http://www.keyongtech.com/2507723-user&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>ServBit everything  about Linux/Windows Server Administration , experts community  &amp;raquo; Blog Archive  &amp;raquo; Power Users &amp;#8212; Advantages &amp;amp; Disadvantages , OS Network Security, Web Hosting ,</title><link>http://blogs.technet.com/jesper_johansson/archive/2006/03/12/421870.aspx#3248258</link><pubDate>Sun, 31 May 2009 13:05:52 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3248258</guid><dc:creator>ServBit everything  about Linux/Windows Server Administration , experts community  &amp;raquo; Blog Archive  &amp;raquo; Power Users &amp;#8212; Advantages &amp;amp; Disadvantages , OS Network Security, Web Hosting ,</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://www.servbit.com/2849_power-users-advantages-disadvantages.html"&gt;http://www.servbit.com/2849_power-users-advantages-disadvantages.html&lt;/a&gt;&lt;/p&gt;
</description></item></channel></rss>